A Virginia-registered offensive cybersecurity startup soliciting vulnerability research is controlled by two men with multiple felony convictions, a pattern of operating under false identities, and no verifiable government contracts.
Summary
- IRIS C2, a startup claiming to pay up to $7 million for zero-day exploits, is linked to Jacob Wohl and Jack Burkman — both convicted felons with documented histories of fraud and fabrication.
- The company operates under the umbrella of Calvexa Group LLC, a registered federal contractor with no confirmed active government contracts.
- Wohl has admitted he operates under pseudonyms in business ventures; former employees of a prior company resigned upon learning his real identity.
- Security researchers approached at conferences are being solicited to submit vulnerability findings to this entity.
- IRIS C2 claims 40 staff, yet none reportedly list the employer on LinkedIn — a significant due-diligence gap for any researcher considering engagement.
What IRIS C2 Claims to Be
Since January 2025, an X/Twitter account called IRIS C2 has been building a public profile in offensive security circles, accumulating over 4,000 followers with posts covering software exploits, AI and security vulnerabilities. The accompanying website, irisc2.com, describes a business based in McLean, Virginia that acquires zero-day exploits, exploit primitives and full capability chains across major platforms, with stated payouts ranging from $10,000 to $7 million depending on the target and operational value. The site also advertises open roles, actively courting junior researchers with high aptitude and no requirement for formal qualifications.
Who Is Actually Behind It
Government contracting records link irisc2.com to Calvexa Group LLC, a Virginia-registered entity. The address on Calvexa Group’s incorporation records corresponds to a property associated with Jack Burkman, a 60-year-old Washington lobbyist. When contacted by KrebsOnSecurity, Burkman redirected questions to his long-term associate Jacob Wohl, aged 28. Wohl confirmed his involvement and said Burkman is not part of day-to-day operations. He described IRIS C2 as having evolved from a penetration testing firm into one focused on selling phone-hacking capabilities to the federal government, though he declined to name any specific contracts.
A Record That Demands Scrutiny
Burkman and Wohl are not unknown quantities. The pair have been prosecuted across multiple US jurisdictions for running robocall campaigns designed to suppress voter turnout, resulting in felony convictions in Ohio for telecommunications fraud in 2022. They were sentenced to probation following a separate 15-count indictment in Cleveland. A New York civil court found they had violated federal and state civil rights laws, leading to a $1 million settlement. The Federal Communications Commission levied a $5.1 million fine against them for robocall activity — at the time the largest ever sought under the Telephone Consumer Protection Act. Wohl also carries earlier convictions: a guilty plea in California in 2019 to four felony counts of selling unregistered securities, and a 2017 securities fraud action in Arizona.
A Pattern of False Identities
Separate from the legal history, Burkman and Wohl have a documented practice of operating businesses under assumed names. Politico reported in September 2024 that their AI lobbying platform LobbyMatic — since shut down — was run with Wohl using the name ‘Jay Klein’ and Burkman presenting as ‘Bill Sanders.’ At least two employees resigned after discovering the real identities of their employers; others only found out after leaving. Wohl’s GitHub account is listed under the name ‘Jay Wohl.’ For any security researcher or potential employee, this history is directly material to assessing whether to engage with IRIS C2.
What Wohl Says About the Operation
In his interview with KrebsOnSecurity, Wohl was candid about several things and evasive about others. He acknowledged he has no formal education or training in computer science or security, describing his knowledge as self-taught. He stated that researchers regularly submit vulnerability findings that are preliminary in nature, and that the company’s role is to develop those primitives into stable, reliable exploits. He claims approximately 40 employees, but said none are permitted to list IRIS C2 on their LinkedIn profiles for operational security reasons. No independent verification of staff numbers, government contracts or specific capabilities was available from the sources reviewed.
How Researchers Are Being Approached
KrebsOnSecurity became aware of IRIS C2 after a conference attendee reported that Wohl and representatives of Calvexa Group were actively soliciting vulnerability researchers at a regional cybersecurity event. The approach — directly targeting practitioners at industry gatherings — suggests the organisation is attempting to build a research pipeline outside of established broker channels.
Why it matters
For CISOs, this story presents two distinct concerns. First, any organisation whose researchers or staff are approached by IRIS C2 should be aware they may be dealing with individuals who have operated under false identities and have multiple felony convictions. Submitting proprietary vulnerability research — even preliminary findings — to an entity whose legitimacy, government relationships and data handling practices cannot be verified carries meaningful legal and reputational risk. Second, the zero-day broker market already operates with limited transparency; the emergence of actors with this profile further complicates due diligence for organisations trying to ensure their researchers engage only with credible, legally sound counterparties. The fact that this entity is actively recruiting at conferences means your teams may encounter them directly.
What to do now
- Brief vulnerability research teams on the existence of IRIS C2 and Calvexa Group LLC, and advise caution before submitting any findings or engaging with representatives at industry events.
- Remind researchers that submitting exploits to unverified brokers may carry legal risk, particularly where export control regulations or employment agreements are relevant.
- If approached by IRIS C2 at conferences or via social media, document the interaction and route it through your legal or compliance function before responding.
- When vetting any offensive security vendor or exploit broker, verify incorporation details, active government contracting records, and the identity of principals — the Calvexa Group/IRIS C2 structure illustrates why surface-level checks are insufficient.
- Establish or reinforce internal policy on what, if anything, researchers may share with third-party brokers outside of pre-approved vendor relationships.
